Novolis Docs
novolis-security / README.md

novolis-security docs

dotnetsecuritynovolis

Token mint, tenant authorization, password hashing, encryption, and HaveIBeenPwned helpers. Not a commercial Identity Provider — see what-this-is.md.

Published docs: https://novolis-platform.github.io/.github/novolis-security/

Guides

DocWhat it covers
what-this-is.mdToken mint + tenant authz framework vs Duende IdentityServer / full IdPs
getting-started.mdInstall, restore from GitHub Packages, first use
design.mdGoals, layer placement, non-goals, credential store isolation
owasp-security-evaluation.mdOWASP ASVS 5.0.0 / API Top 10 / OAuth BCP evaluation of identity, hashing, and crypto libraries
release.mdCalVer publish and package list

Packages

PackageRole
Novolis.Security.CryptographyHelpers
Novolis.Security.EncryptionHelpers
Novolis.Security.HaveIBeenPwnedHelpers
Novolis.Security.OAuth.ClientOutbound Novolis-issuer caller
Novolis.Security.PasswordHashingHelpers
Novolis.Security.Secrets / SecureTextHelpers
Novolis.Security.Authentication.*Application sign-in (not an IdP)
Novolis.Security.OAuth.*Access-token mint (not IdentityServer)
Novolis.Security.Authorization.*Tenant authz framework (not OAuth scopes)

More